Field method

How we examine a control before we write a finding.

This page describes the working method behind our audits for fintech operators. It is the craft we bring to engagements—not a software methodology dressed in new clothes.

Desk with organised folders, checklist, and reading glasses
01

Map the money journey

We sketch the path funds take—customer or merchant onboarding, authorisation, settlement, refunds, and exceptions. The map stays short enough to discuss in one sitting and specific enough to name the systems of record your staff already use.

02

Walk the step, not the policy

Beside operations or compliance staff, we ask them to perform or narrate a recent case. Where the screen, the stamp, or the approval email diverges from the written control, we note the divergence as a candidate finding.

03

Sample with intent

Samples are drawn from populations you help define: settlement dates, product codes, alert types, or loan statuses. We avoid theatrical sample sizes; we choose enough items to test whether a control holds under ordinary pressure.

04

Rate and assign

Findings carry severity ratings tied to operational or regulatory consequence, plus a suggested owner role. We do not invent metrics for marketing; we write what a remediation meeting can use.

What the method refuses

  • Checkbox questionnaires that never open a file
  • Findings written only from policy binders
  • Severity inflation to justify larger fees
  • Vendor referrals tied to the engagement

Where to begin

If settlement breaks, loan overrides, or wallet alerts are already keeping your team late, start with the engagement that matches that pressure. The flagship Payments Control Audit remains the fullest expression of this method.